Lucene search

K
redosRedosROS-20240719-05
HistoryJul 19, 2024 - 12:00 a.m.

ROS-20240719-05

2024-07-1900:00:00
redos.red-soft.ru
6
vulnerability
web application
node.js
exploitation
remote execution
arbitrary code
injection
javascript
express.js
open source
redirect
malicious urls
unix

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.7

Confidence

Low

EPSS

0.001

Percentile

47.9%

A vulnerability in the ejs web application development pattern for Node.Js is related to incorrect neutralization of
special elements in the output data used by the input component. Exploitation of the vulnerability could
allow an attacker acting remotely to execute arbitrary code by injecting specially
specially crafted JavaScript code

A vulnerability in the Express.js web application development pattern for Node.Js is related to an open source redirect using a malformed JavaScript code.
redirects using malformed URLs. Exploitation of the vulnerability could
Allow a remote attacker to redirect users to malicious URLs

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64opensearch< 2.15.0-1UNKNOWN

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.7

Confidence

Low

EPSS

0.001

Percentile

47.9%